OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-93853

HIGH · CVSS 7.2 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Barman versions 3.4.0 to 3.20.0 are vulnerable due to a flaw that allows an attacker with write access to the backup catalog to manipulate the backup.info file, leading to the deletion of unrelated cloud snapshots across AWS, Azure, or Google Cloud. This can result in significant data loss if the attacker substitutes snapshot identifiers, as Barman executes deletion commands without verifying ownership. Organizations using affected Barman versions should prioritize patching to version 3.20.1 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-93853
Severity
HIGH
CVSS
7.2
EPSS
0.21%
Microsoft

Original NVD Description

Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots. When a snapshot backup is deleted, either explicitly or by retention policy enforcement, Barman reads the snapshot identifiers from the backup.info file and passes them to the cloud provider's delete API using Barman's own credentials, without verifying that the snapshots belong to that backup. An attacker who can overwrite backup.info but lacks snapshot delete permissions can substitute the identifiers of other snapshots, causing Barman to delete any snapshot its cloud identity can reach on AWS, Microsoft Azure, or Google Cloud. Exploitation requires a deployment where the principal that writes the backup catalog is separate from the identity Barman uses to delete snapshots. Barman versions from 3.4.0 (Google Cloud), 3.6.0 (Azure), and 3.7.0 (AWS) up to and including 3.20.0 are affected. The issue is fixed in Barman 3.20.1.